The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configuring detection settings

Prev Next

The AMSI module generates alerts or blocks execution when any script matches a rule. You can control the number of alerts generated by using the Confidence Threshold for Alerting section in Policies. The confidence threshold allows you to suppress alerts based on a triggered rule’s confidence level. For example, a High level setting only alerts on rules with a high confidence level, and a Low level setting alerts on every rule. The alert includes an extract of the suspicious script for quick analysis. Use the Context data size option to control the size of the sample script.

When blocking is enabled, the execution of scripts is blocked when a detection matches the selected confidence level or higher. By default, blocking is disabled, alerting is High, and the default data size is 1 KB.

Note

To prevent AMSI blocking a known allowed script, add it to the exclusions rules in policy.

To configure Alerts:

  1. Log in to the Endpoint Security Web UI.

  2. From the Admin menu, select Polices.

  3. On the Policies page, select the policy you want.

  4. On the Edit Policy page, in the Configurations section, select the AMSI tab.

  5. On the AMSI details panel, in the Detection Settings section, select settings for confidence level, blocking, and data size.

  6. Click Save.

AMSI_DetectionSettings.png

Note

Confidence levels are decided by the Trellix research team and applied to each rule. The confidence levels are tuned based on the observations from internal testing and feedback from the field.